Re: [PATCH net] sctp: reject stale cookies with mismatched verification tags
Xin Long <[email protected]> Fri, 24 Jul 2026 11:50:39 -0400
| Newsgroups | org.kernel.vger.linux-sctp,org.kernel.vger.linux-kernel,org.kernel.vger.netdev,org.kernel.vger.stable |
|---|---|
| Message-ID | <CADvbK_d9Q=+dZKy306Bv+PV2AjYbdo0WvX9w7t2=zVMbc=UFJA@mail.gmail.com> |
On Thu, Jul 23, 2026 at 6:56=E2=80=AFPM Yuxiang Yang <[email protected]> wrote: > > sctp_unpack_cookie() skips cookie expiration checks whenever an > association already exists. This is broader than the exception in > RFC 9260 Section 5.2.4. > > For an existing association, Section 5.2.4 permits an expired State > Cookie only when both Verification Tags in the cookie match the current > association. Otherwise, the packet SHOULD be discarded and a Stale > Cookie ERROR MUST be sent. > > The broad check lets an expired Action A restart cookie reach > sctp_sf_do_dupcook_a(). In a runtime test with the default 60 second > cookie lifetime, replaying such a cookie after 65 seconds returned a > COOKIE-ACK and restarted the association. > > Check cookie expiration unless both Verification Tags match. This > preserves the Action D exception for a lost COOKIE ACK while rejecting > expired cookies in all other cases. > > Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") > Cc: [email protected] > Signed-off-by: Yuxiang Yang <[email protected]> > --- > net/sctp/sm_make_chunk.c | 11 +++++++---- > 1 file changed, 7 insertions(+), 4 deletions(-) > > diff --git a/net/sctp/sm_make_chunk.c b/net/sctp/sm_make_chunk.c > index c02809264..a1c0334a1 100644 > --- a/net/sctp/sm_make_chunk.c > +++ b/net/sctp/sm_make_chunk.c > @@ -1802,9 +1802,9 @@ struct sctp_association *sctp_unpack_cookie( > goto fail; > } > > - /* Check to see if the cookie is stale. If there is already > - * an association, there is no need to check cookie's expiration > - * for init collision case of lost COOKIE ACK. > + /* Check to see if the cookie is stale. RFC 9260 Section 5.2.4 > + * exempts an expired cookie only when both Verification Tags mat= ch > + * the current association. > * If skb has been timestamped, then use the stamp, otherwise > * use current time. This introduces a small possibility that > * a cookie may be considered expired, but this would only slow > @@ -1815,7 +1815,10 @@ struct sctp_association *sctp_unpack_cookie( > else > kt =3D ktime_get_real(); > > - if (!asoc && ktime_before(bear_cookie->expiration, kt)) { > + if ((!asoc || > + asoc->c.my_vtag !=3D bear_cookie->my_vtag || > + asoc->c.peer_vtag !=3D bear_cookie->peer_vtag) && > + ktime_before(bear_cookie->expiration, kt)) { > suseconds_t usecs =3D ktime_to_us(ktime_sub(kt, bear_cook= ie->expiration)); > __be32 n =3D htonl(usecs); > > -- > 2.34.1 > Acked-by: Xin Long <[email protected]>